← Back to Skills Marketplace
pipedream941

RegexVisualizer

by Zhong Siyao · GitHub ↗ · v1.0.0
cross-platform ⚠ suspicious
611
Downloads
2
Stars
0
Active Installs
1
Versions
Install in OpenClaw
/install regex-visualizer
Description
Render Regulex-style railroad diagrams for a JavaScript regular expression and export the exact same SVG/PNG as the Regulex-Plus web UI (docs/index.html) "Ex...
Usage Guidance
This skill appears to do exactly what it claims: run a local Node script that loads the included Regulex HTML in a headless browser and writes SVG/PNG output. Before installing, note: (1) npm install will add puppeteer-core and its dependencies to the skill folder; (2) you must have a local Chrome/Edge installed (or set CHROME_PATH/--chrome); (3) the script launches the browser with --no-sandbox (common for headless automation) — only run it on trusted content and in a safe environment; (4) review assets/regulex.html if you have concerns about remote resource loading (the packaged file appears self-contained). If you only need simple diagram rendering and prefer fewer dependencies, consider alternative tools that don't require a headless browser, but from a coherence/security standpoint this package is consistent with its purpose.
Capability Analysis
Type: OpenClaw Skill Name: regex-visualizer Version: 1.0.0 The skill is classified as suspicious due to significant vulnerabilities in `scripts/render.mjs`. The script uses `writeFileSync` with a user-controlled `--out` argument, which, when combined with `path.resolve()`, could allow an attacker to write arbitrary SVG/PNG content to arbitrary file system locations (e.g., using `../` or absolute paths). Additionally, the `--chrome` argument allows specifying an executable path for the headless browser, which could lead to Remote Code Execution if a malicious path is provided. While there is no clear evidence of intentional malicious behavior like data exfiltration or persistence, these vulnerabilities present a high risk of abuse.
Capability Assessment
Purpose & Capability
Name/description match the implementation: the skill embeds Regulex-Plus HTML and provides a Node script that launches puppeteer-core to produce the same SVG/PNG output as the web UI. Required tooling (Node, local Chrome/Edge) is appropriate and documented. No unrelated env vars, binaries, or credentials are requested.
Instruction Scope
SKILL.md instructs running the included scripts, installing puppeteer-core, and supplying a regex/out path. The runtime instructions only read the included assets/regulex.html and write the requested <out>.svg/.png files. There is no instruction to read arbitrary user files, environment secrets, or transmit data to external endpoints. Note: since the HTML is rendered by a browser, if that HTML referenced remote assets it could cause network fetches; the bundled assets appear self-contained.
Install Mechanism
No automatic install spec is present (instruction-only), but package.json depends on puppeteer-core and SKILL.md documents running npm install. This is a normal, proportionate approach. puppeteer-core does not bundle Chromium so the script correctly requires a local browser; package-lock is included and references npm registry packages (expected).
Credentials
The skill requests no credentials or config paths. It optionally respects CHROME_PATH / PUPPETEER_EXECUTABLE_PATH or a --chrome flag to locate the browser, which is reasonable and proportional to launching puppeteer. No secrets are required or accessed.
Persistence & Privilege
always is false and disable-model-invocation is false (normal). The skill does not attempt to persist system-wide configuration, modify other skills, or request permanent elevated presence.
How to Use
  1. Make sure OpenClaw is installed (local or Docker)
  2. Run the install command in chat: /install regex-visualizer
  3. After installation, invoke the skill by name or use /regex-visualizer
  4. Provide required inputs per the skill's parameter spec and get structured output
Version History
v1.0.0
Initial release — export Regulex-style railroad diagrams to PNG and SVG by reusing the original Regulex-Plus web UI renderer. - Generates diagrams from JavaScript regexes, supporting flags i/m/g. - Outputs match the Regulex-Plus web UI's "Export Image" feature exactly. - Command-line interface enables export to SVG and/or PNG. - Surfaces UI error messages for invalid regexes. - No custom rendering; all output is from the embedded Regulex-Plus UI.
Metadata
Slug regex-visualizer
Version 1.0.0
License
All-time Installs 0
Active Installs 0
Total Versions 1
Frequently Asked Questions

What is RegexVisualizer?

Render Regulex-style railroad diagrams for a JavaScript regular expression and export the exact same SVG/PNG as the Regulex-Plus web UI (docs/index.html) "Ex... It is an AI Agent Skill for Claude Code / OpenClaw, with 611 downloads so far.

How do I install RegexVisualizer?

Run "/install regex-visualizer" in the OpenClaw or Claude Code chat to install it in one step — no extra setup required.

Is RegexVisualizer free?

Yes, RegexVisualizer is completely free (open-source). You can download, install and use it at no cost.

Which platforms does RegexVisualizer support?

RegexVisualizer is cross-platform and runs anywhere OpenClaw / Claude Code is available (cross-platform).

Who created RegexVisualizer?

It is built and maintained by Zhong Siyao (@pipedream941); the current version is v1.0.0.

💬 Comments